arXiv:2508.05250eess.AS2025-08中稿 · IEEE Transactions …被引 5

评估语音识别中相似度排名泄露隐私的程度,为生物特征安全提供量化工具。

Privacy Disclosure of Similarity Rank in Speech and Language Processing

  • 通过估计真实身份的相似度排名分布,量化隐私泄露风险。
  • 不同特征编码中,说话人嵌入泄露信息最多,且样本越长泄露越多但受数据库限制。
  • 适用于评估语音、作者等生物特征技术的隐私威胁,支持跨特征整合分析。

在说话人、作者及其他生物特征识别应用中,常通过比较样本与模板库的相似度来确定身份。由于数据噪声和相似度度量不准确,真实身份未必排在最前。然而,即使相似度度量不准,其排名本身仍可能泄露关于真实身份的私密信息。本文提出一种量化相似度排名隐私泄露的方法,通过估计其概率分布实现:当数据充足时使用直方图,数据稀少时采用贝塔-二项分布建模。以熵(比特)表示泄露程度,使独立特征的泄露可叠加。实验表明,所有测试的说话人与作者表征均包含可用于识别的个人身份信息(PII),其中说话人识别模型嵌入信息最多,其次为电话嵌入、语言嵌入和基频。初步实验显示,测试样本越长,泄露越多,但受数据库模板长度限制。该指标可比较不同生物特征的隐私泄露程度,并支持融合多特征以辅助识别,有助于全面评估语音及其他生物特征技术的隐私风险。

原文摘要 · Abstract (English)

Speaker, author, and other biometric identification applications often compare a sample's similarity to a database of templates to determine the identity. Given that data may be noisy and similarity measures can be inaccurate, such a comparison may not reliably identify the true identity as the most similar. Still, even the similarity rank based on an inaccurate similarity measure can disclose private information about the true identity. We propose a methodology for quantifying the privacy disclosure of such a similarity rank by estimating its probability distribution. It is based on determining the histogram of the similarity rank of the true speaker, or when data is scarce, modeling the histogram with the beta-binomial distribution. We express the disclosure in terms of entropy (bits), such that the disclosure from independent features are additive. Our experiments demonstrate that all tested speaker and author characterizations contain personally identifying information (PII) that can aid in identification, with embeddings from speaker recognition algorithms containing the most information, followed by phone embeddings, linguistic embeddings, and fundamental frequency. Our initial experiments show that the disclosure of PII increases with the length of test samples, but it is bounded by the length of database templates. The provided metric, similarity rank disclosure, provides a way to compare the disclosure of PII between biometric features and merge them to aid identification. It can thus aid in the holistic evaluation of threats to privacy in speech and other biometric technologies.

隐私泄露生物特征语音识别信息熵

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。